SUSE-SU-2026:4062-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4062-1
SUSE-SU-2026:4062-1
Summary: Security update for terraform-provider-null
Details: This update for terraform-provider-null fixes the following issues: - CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278269). - CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278272). - gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1278267).
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264062-1/, https://bugzilla.suse.com/1278267, https://bugzilla.suse.com/1278269, https://bugzilla.suse.com/1278272, https://www.suse.com/security/cve/CVE-2026-84303, https://www.suse.com/security/cve/CVE-2026-84304
Affected packages
Package
Name: terraform-provider-null
Purl: pkg:rpm/suse/terraform-provider-null&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
